Invisible Watermark Embedding for Protected Image Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for protecting machine learning models, such as digital watermarks, either fail to prevent unauthorized use or significantly degrade the visual quality and practicability of the models, making them ineffective for practical applications.
Innovation Solution
A method involving an embedding network to invisibly embed a watermark in the output images generated by a target image converter, which can be extracted by a corresponding extraction network to detect unauthorized use, without affecting the visual quality or training process of the model.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If digital watermarks are embedded in model outputs to protect machine learning models, then model protection capability is improved, but visual quality and practicability of the model outputs deteriorate
Solution Approach 1:
The patent applies local quality by embedding watermarks only in specific frequency domains (high-frequency components) rather than uniformly across the entire image. This selective approach protects the model output while preserving visual quality in the perceptible frequency ranges.
Solution Approach 2:
The patent transforms the watermark embedding problem from spatial domain to frequency domain, changing the parameter space where watermarks are embedded. By operating in the frequency domain and targeting specific frequency bands, the system achieves both protection and visual quality preservation.
2Reliability
If visible watermarks are added to protect machine learning models, then model protection capability is improved, but ease of operation and user experience deteriorate
Solution Approach 1:
The patent makes the watermark imperceptible to human users by embedding it only in high-frequency components that are less sensitive to human visual perception. This maintains ease of operation and user experience while providing model protection.
Solution Approach 2:
The patent effectively changes the 'visibility' parameter of the watermark by transforming it from visible (in spatial domain) to invisible (in frequency domain representation), while it remains detectable by extraction systems.
3Reliability
If traditional watermarking methods are used to prevent unauthorized use, then model protection capability is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent replaces traditional spatial-domain watermarking mechanisms with frequency-domain processing. This substitution enables more efficient embedding and extraction operations while reducing processing overhead and system complexity.
Data Source
AI summary
Embodiments of the present disclosure relate to a method, a device, and a computer program product for image processing. The method includes generating from an input image a corresponding output image, and determining watermark embedding of a target watermark by an embedding network. The method further includes generating, by the embedding network, a watermarked image corresponding to the output image based on the output image and the watermark embedding, wherein the target watermark is invisible in the watermarked image and can be extracted from the watermarked image by an extraction network corresponding to the embedding network. Without reducing the practicability of an image generation tool, this solution can provide more effective protection for an image generated thereby and the tool itself so as to prevent theft of the image and functions of the tool.


